Millions of LinkedIn passwords put up for sale following 2012 hack

LinkedIn

There's bad news for some LinkedIn users, as a ton of account details for the social network have just gone on sale, even though they were pilfered in a security breach that happened years ago.

You may recall the breach which happened in 2012 and apparently resulted in 6.5 million passwords being stolen, but it seems the true gravity of this incident is only now being realised.

Motherboard spoke to the hacker who has posted the fresh account details for sale online, and the individual known as 'Peace' claims there are no less than 167 million accounts involved, although only 117 million of these have both emails and hashed passwords.

Those are hugely worrying numbers, and unsurprisingly LinkedIn has already responded to this news with a blog post.

LinkedIn said it was aware of a new set of data which has just been released claiming to be the details of over 100 million accounts, and the social network is taking this very seriously, saying it is introducing "immediate steps to invalidate the passwords of the accounts impacted".

Those account owners will be contacted by LinkedIn to reset their passwords, so if you have been affected, you've probably already heard about it or will do very shortly.

Making a hash of it

LinkedIn also noted that back in 2012 at the time of the breach, its response included a mandatory password reset for accounts the social network believed to be compromised, but that number was far smaller than the true figure if this leak is indeed kosher. Which it certainly sounds like it is.

When this incident happened four years ago, LinkedIn got into trouble for failing to "salt" password hashes before storing them on servers, meaning even though the passwords obtained were encrypted, the encryption wasn't as watertight as it should have been.

This resulted in a class-action lawsuit being filed against the social media site, so it was quite a traumatic affair for LinkedIn all round – but the pain isn't over yet, it would seem.

In its blog post, LinkedIn reminded us that it now hashes and salts every password, and also urged members to make use of two-factor authentication which the site supports, to prevent an attacker from accessing an account even if they do manage to learn the password.

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Cyber Crime
A person scanning a QR code on a smartphone
Quishing is the new QR code scam you need to watch out for – here's how to stay safe
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Text Phishing Scams
Do not fall for this dangerous Amazon shopping scam
Cyber-security
Safeguarding against next-gen cyber risks
The North Face jacket
Thousands of North Face customers accounts hacked, personal data stolen
Smartphone hacked with data flow in the background
9 signs your phone has been hacked
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does